Sized local asset manifests

A schemaVersion1 local browser manifest may give each entry a safe integer size (bytes) and loadMode:

required with optional:true is contradictory and rejected. Background startup is idempotent within one running-host lifetime. A load after stop creates a fresh lifetime and warmup queue; old providers retain their cancelled signal. Legacy entries without loadMode keep their existing behavior. Existing httpRange discovery and measured preloadRanges are unchanged. Explicit lazy/background modes cannot also request synchronous image decoding or launch preloads. Aliases of the same URL share one provider; contradictory size/mode declarations fail validation. A provider's lifetime signal is separate from the launch download signal.

Candidate preparation (tools/fetch-candidate-corpus.js --id=ID --prepare) emits exact stat sizes. A candidate's browser policy can set defaultLoadMode and per-relative-path fileLoadModes. Regardless of a lazy default, EXE/DLL/OCX/VBX/DRV/TTF/TTC/FON stay required. Both Dredmor candidates opt in; no game bytes are committed. Regenerate the ignored local manifests when changing policy or fixture contents. The served server must support206 responses for the declared single-file URL; the first actual response must report a Content-Range matching both requested offsets and declared total; wrong sizes/range failures surface on read, not as a successful eager fallback. Split-release URLs still use the legacy discovery path unless explicitly prepared as independently sized assets.

Validation includes actual host/VFS mounting of6000 files with zero startup requests, sparse reads, aliases, metadata rejection, cancellation, required failures, background bounds/stop/errors, and actual preparation with native/font classification. This establishes loader behavior, not Dredmor startup or gameplay compatibility; those require a recorded ordinary launch.